Stablecoin Issuers Freeze $318K in Stolen Funds Following Bitget Exchange Breach

2 hours ago 6

Key Takeaways

  • Stablecoin issuers Circle and Tether successfully froze approximately $318,000 in USDC and USDT connected to the Bitget security breach.
  • The exchange revised its stolen asset calculation upward to $387.5 million from an initial $351.6 million estimate.
  • A bounty initiative offers 5% rewards for freezing stolen assets and an additional 5% for successful recovery efforts.
  • Bitget claims to have identified the intrusion method and addressed the security flaw exploited in the attack.
  • A phased withdrawal reopening schedule begins September 28, starting with Bitcoin transactions.

Bitget, one of the prominent cryptocurrency trading platforms, continues to navigate the consequences of a significant security breach that targeted its infrastructure earlier this week. Initially, the platform calculated its losses at $351.6 million. That figure has now been adjusted to $387.5 million.

Circle and Tether Freeze $318,000 Linked to Bitget Hack

According to CoinDesk, Circle and Tether blacklisted an address labeled "Bitget Exploiter 8," freezing 218,023 USDT and 99,990 USDC, worth approximately $318,000 combined. Circle took action at 05:00 UTC on September 25,… pic.twitter.com/0CLm2oKVVZ

— Wu Blockchain (@WuBlockchain) September 26, 2026

The security incident occurred on September 24. The exchange discovered unauthorized fund movements from several hot wallets at 18:31 UTC on that date. While hot and warm wallet storage was compromised, cold wallet reserves remained untouched.

According to Bitget CEO Gracy Chen, the perpetrators gained access through a backend system connected to the exchange’s wallet management architecture. She explained that they manipulated transaction information to activate the wallet’s approval mechanism. Chen specifically dismissed the possibility of a compromised private key.

Stablecoin Companies Take Swift Action to Blacklist Assets

Both Circle and Tether responded promptly following the security breach. Circle placed a wallet containing stolen assets on its blacklist at 05:00 UTC Friday. This wallet contained approximately 170 ETH, 218,023 USDT and 99,990 USDC.

Thank you to Circle and Tether for moving quickly. Every address frozen matters.

To the broader community: Bitget's Recovery Bounty Program is live — 5% for freezing attacker funds, 5% for recovery. Every exchange, security researcher, and onchain investigator can make a… https://t.co/UrFjceBL49

— Gracy Chen @Bitget (@GracyBitget) September 26, 2026

Tether implemented a ban on the identical wallet moments later, as confirmed by blockchain security firm MistTrack. Combined, these two organizations immobilized roughly $318,000 worth of stablecoins.

This sum represents only a fraction of the overall damages. MistTrack reported that additional addresses associated with the attacker continue to hold over 63,000 ETH. Unlike stablecoins, Ether lacks a centralized authority capable of freezing assets.

Security analyst Taylor Monahan monitored portions of the stolen USDC as it transferred across various wallets. She noted that some of these funds were exchanged for ETH throughout the process.

Bitget increased its comprehensive loss calculation after incorporating assets from two blockchain networks initially overlooked. The organization stated the revised $387.5 million amount now encompasses affected holdings on Zcash and TRON.

According to Bitget, this revision provides a more complete picture of the initial security breach. The update does not indicate any additional unauthorized transactions.

The inventory of compromised assets is extensive. It encompasses XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.

Investigators have pinpointed four primary addresses receiving the stolen cryptocurrency. These addresses are distributed across EVM-compatible networks, XRP Ledger, Zcash and TRON.

Exchange Introduces Reward Initiative for Asset Recovery

Chen unveiled a reward program via X this week. The initiative solicits assistance from exchanges, security professionals and blockchain analysts in locating the misappropriated funds.

The initiative features two distinct compensation tiers. Contributors can receive 5% of any assets they assist in freezing, plus an additional 5% for assets they help retrieve.

Bitget clarified that measures implemented prior to the bounty announcement remain eligible. The platform will determine qualification criteria and assign value to individual contributions.

Court-ordered or law enforcement-mandated asset freezes are excluded from bounty eligibility.

Bitget established a public monitoring dashboard to provide real-time tracking of the stolen cryptocurrency. The company also launched a submission portal for information regarding the attacker’s wallet addresses.

The platform confirmed that Mandiant and SlowMist are assisting with the investigation. Bitget reports successfully identifying the attack vector and resolving the exploited security weakness.

The organization maintains that additional unauthorized transactions are no longer feasible.

Bitget has outlined a gradual withdrawal restoration timeline. Bitcoin withdrawals recommence September 28. Ethereum-based withdrawals will follow on September 29, with USDT on September 30, and remaining tokens plus fiat currencies by October 2.

Bitget emphasized that user account balances have not been impacted. The company referenced its Protection Fund, previously valued above $464 million, as the financial safeguard covering the losses. No updated fund valuation has been released corresponding to the new $387.5 million loss figure.

Chen plans to conduct a live question and answer session on September 28 at 07:30 UTC to address the situation and outline the exchange’s recovery strategy.

The post Stablecoin Issuers Freeze $318K in Stolen Funds Following Bitget Exchange Breach appeared first on Blockonomi.

Read Entire Article